Vulnerability Details CVE-2009-2304
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2009-2304
-
cpe:2.3:a:avatic:aardvark_topsites_php:*
-
cpe:2.3:a:avatic:aardvark_topsites_php:4.0.2
-
cpe:2.3:a:avatic:aardvark_topsites_php:4.1.1
-
cpe:2.3:a:avatic:aardvark_topsites_php:4.2.2
-
cpe:2.3:a:avatic:aardvark_topsites_php:5
-
cpe:2.3:a:avatic:aardvark_topsites_php:5.0.3
-
cpe:2.3:a:avatic:aardvark_topsites_php:5.1.2